announce
Thread
Date
Earlier messages
Messages by Thread
[ANNOUNCE] Apache Grails 7.2.3
James Daugherty
[ANNOUNCE] Apache Grails 7.1.6
James Daugherty
[ANNOUNCE] Apache Grails 7.0.16
James Daugherty
[ANNOUNCE] Apache XTable 0.4.0-incubating released
Vinish Reddy
CVE-2026-55976: Apache Hive: SSRF vulnerability in Hive Avro Serde due to Insufficient input validation on avro.schema.url
Sai Hemanth Gantasala
CVE-2026-53561: Apache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation allows impersonation of any Hive user
Sai Hemanth Gantasala
CVE-2026-49845: Apache Hive: SQL Injection vulnerability in HiveMetaStore partition-name direct-SQL paths
Sai Hemanth Gantasala
CVE-2026-75005: Apache APISIX: Unauthenticated CPU-exhaustion DoS
Abhishek Choudhary
CVE-2026-75020: Apache APISIX: ldap-auth plugin cross-subtree identity impersonation
Abhishek Choudhary
CVE-2026-74848: Apache APISIX: Cross-user response poisoning in serverless plugins
Abhishek Choudhary
[ANNOUNCE] Apache Pulsar C# Client DotPulsar 5.3.3 released
David Jensen
CVE-2026-63041: Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers
Abhishek Choudhary
[ANNOUNCE] Apache APISIX 3.18.0 has been released
Abhishek Choudhary
[SECURITY] CVE-2026-68569 Apache Tomcat - Principal lookup can fail open in some cases
Mark Thomas
[SECURITY] CVE-2026-73180 Apache Tomcat - Authenticated WebSocket session survives end of HTTP session
Mark Thomas
[SECURITY] CVE-2026-68763 Apache Tomcat - DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
Mark Thomas
[SECURITY] CVE-2026-68525 Apache Tomcat - Redirect after FORM authentication may bypass method specific constraints
Mark Thomas
[SECURITY] CVE-2026-66422 Apache Tomcat - Servlet role references can bypass declarative role constraints
Mark Thomas
[SECURITY] CVE-2026-65637 Apache Tomcat - HTTP/2 no-authority bypass of strict SNI validation
Mark Thomas
[SECURITY] CVE-2026-65927 Apache Tomcat - RewriteValve [N] restarts at the second rule and may bypass access control
Mark Thomas
[SECURITY] CVE-2026-65905 Apache Tomcat - Limited replay attack possible with DIGEST authentication
Mark Thomas
[SECURITY] CVE-2026-65182 Apache Tomcat - Security constraint bypass
Mark Thomas
[SECURITY] CVE-2026-65183 Apache Tomcat - TOCTOU when setting specific permissions for Unix Domain Sockets
Mark Thomas
[ANNOUNCE] Apache XMLBeans 5.4.0 release
PJ Fanning
Fwd: [ANNOUNCE] Apache Hive 4.2.1 Released
Sai Hemanth Gantasala
CVE-2026-66906: Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
Andrea Cosentino
[ANNOUNCE] Apache Allura 1.20.0 released
Dave Brondsema
CVE-2026-75099: Apache Allura: Unauthenticated REST disclosure
Dave Brondsema
CVE-2026-66907: Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
Andrea Cosentino
CVE-2026-63621: Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
Andrea Cosentino
CVE-2026-71300: Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection
Andrea Cosentino
CVE-2026-60093: Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
Andrea Cosentino
CVE-2026-59230: Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
Andrea Cosentino
CVE-2026-66908: Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
Andrea Cosentino
CVE-2026-78329: Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
Andrea Cosentino
[ANN] Maven Resolver 2.0.22 Released
Tamás Cservenák
[ANNOUNCE] Apache Airflow Providers prepared on 2026-08-18 are released
Hussein Awala
Fwd: [ANNOUNCE] Apache JSPWiki 3.0.0 released
Alex O'Ree
Fwd: [ANNOUNCE] Apache JSPWiki 2.12.5 released
Alex O'Ree
[ANNOUNCE] Apache Avro 1.12.2 released
Ryan Skraba
[ANNOUNCE] Apache Pekko Connectors Kafka 1.2.0 released
PJ Fanning
[ANNOUNCE] Apache SedonaDB 0.4.1 released
Jia Yu
[ANNOUNCE] Apache Tika 4.0.0 released
Tim Allison
[ANNOUNCE] Apache log4net 3.4.0 released
Jan Friedrich
[ANNOUNCE] Apache Casbin (Incubating) 3.11.0 released
Yanrui Zhang
[ANNOUNCE] Release Apache Paimon Vector Index 0.4.0
jerry jing
[ANNOUNCE] Apache Pekko (Core) 1.7.0 released
PJ Fanning
[ADVISORY] Apache CloudStack LTS Security Releases 4.20.3.1 and 4.22.1.1
Abhishek Kumar
Re: [ADVISORY] Apache CloudStack LTS Security Releases 4.20.3.1 and 4.22.1.1
Abhishek Kumar
[ANNOUNCE] Release Apache OpenDAL 0.58.2
Erick Guan
CVE-2026-63038: Apache InLong: SQL Injection via String Concatenation Vulnerability Report
Charles Zhang
CVE-2026-63042: Apache InLong: Missing authorization on DataNode management endpoints
Charles Zhang
CVE-2026-63043: Apache InLong: Agent path traversal via unvalidated file source path
Charles Zhang
CVE-2026-63040: Apache InLong: Missing authorization in StreamSource forceDelete
Charles Zhang
CVE-2026-63016: Apache InLong: Ordinary users can create new packages
Charles Zhang
CVE-2026-63044: Apache InLong: Authenticated SSRF via POST /api/node/testConnection
Charles Zhang
CVE-2026-63039: Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService
Charles Zhang
CVE-2026-63037: Apache InLong: Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endpoint
Charles Zhang
CVE-2026-63015: Apache InLong: Non-template responsible persons can view template information
Charles Zhang
[ANNOUNCE] Release Apache InLong 2.4.0
Verne Deng
[ANNOUNCE] Release Apache Hop 2.19.0
Bart Maertens
[ANNOUNCE] Apache DataSketches Rust 0.4.0 released
tison
[ANNOUNCE] Apache APISIX Ingress controller v2.2.0 released
Xin Rong
[ANN] Apache Tomcat 9.0.121 available
Rémy Maucherat
[ANN] Apache Tomcat 11.0.25 Available
Mark Thomas
[ANNOUNCE] Apache Traffic Server 10.2.0 Release
Chris McFarlen
[ANNOUNCE] Apache Qpid protonj2 1.3.0 released
Timothy Bish
[ANNOUNCEMENT] HttpComponents Client 5.7-alpha1 Released
Oleg Kalnichevski
[ANNOUNCE] Apache Camel 4.18.4 (LTS) Released
Gregor Zurowski
[ANNOUNCE] Apache Fory 1.6.1 released
Shawn Yang
[ANNOUNCE] Apache Ratis 3.3.0 Release
Xinyu Tan
[ANNOUNCE] Apache Camel 4.14.9 (LTS) Released
Gregor Zurowski
[ANNOUNCE] Apache Texera 1.2.0-incubating released
Xuan Gu
[ANNOUNCE] Apache Groovy 6.0.0-beta-2 Released
Paul King
[ANNOUNCE] Apache Groovy 5.1.0 Released
Paul King
[ANN] CVE-2026-73633: Apache Struts: Unbounded read of a JSON request body - S2-072
Lukasz Lenart
[ANNOUNCE] Apache Pulsar C# Client DotPulsar 5.3.2 released
David Jensen
[ANN] CVE-2026-73634: Apache Struts: Unbounded read of a Content Security Policy violation report - S2-073
Lukasz Lenart
[ANN] CVE-2026-73635: Apache Struts: Unbounded growth of localized-text caches driven by the request locale - S2-074
Lukasz Lenart
[ANN] CVE-2026-73631: Apache Struts: Shared parsing state in the JSON plugin - S2-070
Lukasz Lenart
[ANN] CVE-2026-73632: Apache Struts: Shared serialization state in the JSON plugin - S2-071
Lukasz Lenart
[ANNOUNCE] Apache Bigtop 3.6.0 released
Masatake Iwasaki
CVE-2026-66256: Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API)
Arnout Engelen
CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
Oleg Kalnichevski
CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
Oleg Kalnichevski
CVE-2026-73240: Apache Allura: Git command injection
Dave Brondsema
CVE-2026-73237: Apache Allura: XSS in markdown pipeline
Dave Brondsema
CVE-2026-73239: Apache Allura: Missing permission checks IDOR
Dave Brondsema
CVE-2026-73238: Apache Allura: XSS in code display
Dave Brondsema
[ANNOUNCE] Apache Arrow 25.0.1 released
Raúl Cumplido
[ANNOUNCE] Apache Lucene 10.5.1 released
Ignacio Vera
Fwd: [ANNOUNCE] Apache Commons Collections 4.6.0
Gary Gregory
CVE-2026-58076: Apache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API Server
Rahul Vats
CVE-2026-68970: Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI
Rahul Vats
CVE-2026-67260: Apache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next_kwargs deserialization
Rahul Vats
CVE-2026-68969: Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext
Rahul Vats
CVE-2026-68076: Apache Airflow: Connections test API: team-scope guard bypass resolves another team's environment Connection
Rahul Vats
CVE-2026-68971: Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints
Rahul Vats
CVE-2026-68968: Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id
Rahul Vats
CVE-2026-65017: Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)
Rahul Vats
CVE-2026-67587: Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadget
Rahul Vats
CVE-2026-54183: Apache Airflow: Airflow Variables were not masked in the UI for authenticated users
Rahul Vats
CVE-2026-59242: Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint
Rahul Vats
CVE-2026-59244: Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI
Rahul Vats
[ANNOUNCE] Apache Airflow 3.3.1 Released
Rahul Vats
CVE-2026-68868: Apache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables
Jarek Potiuk
[ANNOUNCE] Apache Qpid JMS 1.17.0 released
Robbie Gemmell
[ANNOUNCE] Apache Qpid JMS 2.11.0 released
Robbie Gemmell
CVE-2026-69223: Apache Allura: Server-side request forgery
Dave Brondsema
[ANN] Apache Struts 7.3.0
Lukasz Lenart
[ANN] Apache Struts 6.11.0
Lukasz Lenart
Fwd: [ANNOUNCE] Apache Airflow Providers prepared on 2026-08-08 are released
Jarek Potiuk
CVE-2026-68872: Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-scope guard bypass resolves another team's Connection or Variable
Jarek Potiuk
CVE-2026-68870: Apache Airflow Microsoft Azure provider: microsoft.azure Key Vault backend: team-scope guard bypass resolves another team's Connection or Variable
Jarek Potiuk
CVE-2026-68871: Apache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypass resolves another team's Connection or Variable
Jarek Potiuk
[ANNOUNCE] Apache ActiveMQ 6.3.1 has been released!
Christopher Shannon
[ANNOUNCE] Apache ActiveMQ 5.19.10 has been released!
Christopher Shannon
[ANNOUNCE] Apache ActiveMQ 6.2.9 has been released!
Christopher Shannon
[ANNOUNCEMENT] HttpComponents Client 5.6.4 Released
Oleg Kalnichevski
CVE-2026-44630: Apache IoTDB: RPC service denial of service via unchecked Thrift string length
Haonan Hou
CVE-2026-65948: Apache Ranger: UnixAuth lacks brute-force protection
Velmurugan Periasamy
CVE-2026-55814: Apache Ranger: Download APIs expose plugin data without authentication
Velmurugan Periasamy
CVE-2026-65945: Apache Ranger: Logs contain replayable JWT bearer tokens
Velmurugan Periasamy
CVE-2026-65942: Apache Ranger: Clients accept TLS certificates issued for other hostnames
Velmurugan Periasamy
CVE-2026-55799: Apache Ranger: Remote Code Execution Vulnerability in GraalScriptEngineCreator
Velmurugan Periasamy
CVE-2026-44416: Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation
Velmurugan Periasamy
CVE-2026-42537: Apache Ranger: Remote Code Execution via JDBC URL Injection
Velmurugan Periasamy
CVE-2026-40920: Apache Ranger: Privilege Escalation via URL Parameter
Velmurugan Periasamy
CVE-2026-32227: Apache Ranger: SQL Injection vulnerability in lookup functionality
Velmurugan Periasamy
CVE-2026-28672: Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder
Velmurugan Periasamy
[ANNOUNCE] Apache Airflow Providers prepared on 2026-08-06 are released
Jarek Potiuk
[ANNOUNCE] Apache Ranger 2.9.0 released
Madhan Neethiraj
CVE-2026-61899: Apache Tapestry: Possible classpath file download through URL manipulation
Thiago Henrique De Paula Figueiredo
[ANNOUNCE] Apache Qpid proton-dotnet 1.1.0 released
Timothy Bish
[ANNOUNCE] Apache Fory 1.6.0 released
Shawn Yang
CVE-2026-71559: Apache Fory: Uncaught panic (remote DoS) in Go meta-string decoder from untrusted metadata
Chaokun Yang
CVE-2026-71558: Apache Fory: Heap type confusion in C++ polymorphic smart-pointer deserialization
Chaokun Yang
CVE-2026-71560: Apache Fory: Out-of-bounds heap read in C++ struct deserializer tagged-int fast-path
Chaokun Yang
[ANNOUNCE] Apache Paimon 2.0.0 released
Jingsong Lee
[ANNOUNCEMENT] Apache SkyWalking Go 0.7.0 Released
han liu
[ANN] Maven Resolver Ant Tasks 2.0.0 released
Tamás Cservenák
[ANNOUNCE] Apache Jackrabbit 2.22.4 released
Julian Reschke
[ANNOUNCE] Apache Grails 7.0.15
James Fredley
[ANNOUNCE] Apache Grails 8.0.0-M5
James Fredley
[ANNOUNCE] Apache Grails 7.1.5
James Fredley
[ANNOUNCE] Apache Grails 7.2.2
James Fredley
CVE-2026-34191: Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
Eric Covener
CVE-2026-34502: Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client
Eric Covener
CVE-2026-34501: Apache Portable Runtime Utility: Heap buffer overflow in APR redis client
Eric Covener
CVE-2026-32327: Apache Portable Runtime Utility: apr-util XML stack recursion crash
Eric Covener
CVE-2025-49506: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
Eric Covener
[ANNOUNCEMENT] Apache Portable Runtime Utility 1.6.4 Released
covener
CVE-2026-68481: Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
Colm O hEigeartaigh
CVE-2026-68079: Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay
Colm O hEigeartaigh
CVE-2026-65583: Apache CXF: Self-issued ID token claims validation skipped
Colm O hEigeartaigh
CVE-2026-63687: Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters
Colm O hEigeartaigh
CVE-2026-61466: Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
Colm O hEigeartaigh
CVE-2026-57818: Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider
Colm O hEigeartaigh
CVE-2026-57817: Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow
Colm O hEigeartaigh
CVE-2026-66909: Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage
Colm O hEigeartaigh
CVE-2026-65432: Apache CXF: XXE via WSDL/XSD import parsing
Colm O hEigeartaigh
CVE-2026-64958: Apache CXF: Denial of service via message header attachments
Colm O hEigeartaigh
CVE-2026-57819: Apache CXF: No default restriction on the amount of form parameters per message
Colm O hEigeartaigh
CVE-2026-54225: Apache CXF: Denial of Service attack via large attachments
Colm O hEigeartaigh
CVE-2026-64640: Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation
Alexandre Dutra
[ANNOUNCE] Apache HBase 3.0.0 is now available for download
Duo Zhang
CVE-2026-60053: Apache Answer: Residual Administrative API Key Access After Role or Account Revocation
Enxin Xie
CVE-2026-48912: Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL
Enxin Xie
CVE-2026-60023: Apache Answer: Unauthorized disclosure of deleted or pending answer content
Enxin Xie
CVE-2026-50749: Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions
Enxin Xie
CVE-2026-48911: Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow
Enxin Xie
CVE-2026-48834: Apache Answer: Denial of service via crafted Accept-Language header parsing
Enxin Xie
[ANNOUNCE] Apache Sedona 1.9.1 released
Jia Yu
CVE-2026-61486: Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input
Piotr Karwasz
CVE-2026-61485: Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index
Piotr Karwasz
CVE-2026-61484: Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS
Piotr Karwasz
CVE-2026-61483: Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS
Piotr Karwasz
[ANNOUNCE] Apache BVal 3.1.0
Markus Jung
[ANNOUNCE] Apache Qpid protonj2 1.2.0 released
Timothy Bish
CVE-2026-67592: Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming delivery
Timothy A. Bish
CVE-2026-67591: Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded
Timothy A. Bish
CVE-2026-67590: Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow
Timothy A. Bish
CVE-2026-67589: Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authentication
Timothy A. Bish
CVE-2026-67588: Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Timothy A. Bish
CVE-2026-67553: Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded
Timothy A. Bish
CVE-2026-67555: Apache Qpid Proton Dotnet: Unable to govern the maximum number of transfer frames per incoming delivery
Timothy A. Bish
CVE-2026-67554: Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service
Timothy A. Bish
CVE-2026-67552: Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow
Timothy A. Bish
CVE-2026-67551: Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pre-authentication
Timothy A. Bish
CVE-2026-67465: Apache Qpid Proton Dotnet: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Timothy A. Bish
CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service
Daniil Kirilyuk
CVE-2026-68078: Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery
Daniil Kirilyuk
CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control window can be exceeded
Daniil Kirilyuk
CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service
Daniil Kirilyuk
CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Daniil Kirilyuk
CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow
Daniil Kirilyuk
CVE-2026-68060: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication
Daniil Kirilyuk
[ANNOUNCE] Apache Qpid Proton-J 0.35.0 released
Robbie Gemmell
CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service
Robbie Gemmell
CVE-2026-66277: Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery
Robbie Gemmell
Earlier messages